Last updated: August 3, 2026
KeepFlow L.L.C-FZ is the controller of the personal data described here, meaning we decide why and how it is processed. This policy covers the meeto website, the meeting service, our mobile apps and our meeting widgets (the “Service”).
When an organisation hosts the meeting. If your employer, school or another organisation uses meeto for meetings, that organisation decides whether meetings are recorded or processed by AI and what happens to the results. For that meeting content we act on its instructions as a processor, and the organisation is the controller. Ask that organisation about its own privacy notice first; we will help it respond to you. For accounts, billing, security and the operation of the Service itself, we remain the controller.
You sign in with Google or Apple, and we receive your name, email address and profile picture. With Apple you can hide your email address — we then receive Apple's private relay address instead. We store your plan, settings, meeting history, booking configuration and working hours, and — if you connect a calendar — the calendar events needed to show and schedule your meetings.
No account, no email. We store the display name you type, the meeting you joined and when you joined and left.
Room link, entry mode, start and end time, duration, number of participants, display names, and which features were used. We need this to run the meeting, apply plan limits and show hosts their history.
IP address, approximate location derived from it, browser and device characteristics, operating system, connection quality metrics, and the device and network signals used for anti-abuse (section 6). Also diagnostic and error logs.
Stripe processes payments. We receive your subscription status, billing country, and the card brand and last four digits — never the full card number.
If you join a team workspace, your name, email and role are visible to the other members of that workspace. The workspace owner and admins also see per-seat activity counters (such as the number of meetings in the last 30 days) — never the content, participants, recordings, transcripts or recaps of your meetings.
Messages you send us and the service emails we send you, such as “your recap is ready”.
Audio, video, screen share and chat are encrypted while travelling over the network using the standard WebRTC protections (DTLS-SRTP). Small meetings connect participants directly to each other where the network allows. Larger meetings, and meetings where recording or AI is on, are relayed through our media servers, which means the media is decrypted there in order to be routed, recorded or transcribed.
So, plainly: meeto is encrypted in transit, but it is not end-to-end encrypted in the strict sense. If nobody turns on recording or AI, we do not store the content of your call — media passes through and is gone. In-meeting chat exists only for the duration of the meeting and is deleted when it ends.
These are off by default. They start only when a participant presses the button, and everyone in the room sees a badge while they run. Participants present when it starts are asked to agree; anyone joining later sees that it is on before they enter. Leaving is always an alternative.
When they are on, audio — and video, for recording — is processed to produce the file, the transcript and the summary. Speech-to-text and summarisation are performed by specialist providers under contracts that bar them from using the content for their own purposes. Your meeting content is never used to train AI models, by us or by them.
Voice recordings and transcripts can reveal a lot, including things people say about their health or beliefs. We do not analyse recordings to infer such characteristics, and we do not use voice data for biometric identification of anyone.
Recordings and recaps are published on a meeting page that anyone with the link can open without signing in. Hosts control whether that page exists and can delete it. If you are a guest and want your own copy of a recap, you will need to create an account; that copy then lives in your account and you can delete it.
Where the GDPR or a similar law applies, these are our purposes and legal bases:
| What we do | Legal basis |
|---|---|
| Run meetings — connect participants, relay media, show names, apply plan limits | Performance of our contract with you |
| Accounts, scheduling, booking pages, calendar connections | Performance of our contract |
| Record, transcribe and summarise a meeting | Consent of the participants, collected in the room; for organisation-hosted meetings, on the instructions of that organisation |
| Take payment, invoice, keep accounting records | Performance of our contract; legal obligation |
| Keep the Service secure — anti-abuse, bot and fraud detection, rate limits, incident investigation | Our legitimate interest in protecting the Service and its users |
| Fix problems and improve reliability — diagnostics, error logs, aggregated usage statistics | Our legitimate interest in a service that works |
| Service emails — recap ready, plan and policy changes | Performance of our contract |
| Product news and offers | Consent, or our legitimate interest where the law permits; you can unsubscribe at any time |
| Optional analytics cookies | Consent |
| Answer legal requests, enforce our terms, defend claims | Legal obligation; our legitimate interest |
We do not show third-party advertising, we do not sell personal data, and we do not build advertising profiles.
Anyone can start a meeting without an account, which is also an invitation to abuse. To keep that open door workable, we run automated checks on device and network signals to detect bots, automation tools and account farming. The checks are carried out by a device-intelligence service operated by another company in our group, they work without cookies, and they are used for nothing except protecting the Service. Occasionally an honest user is asked to confirm they are a person; normally you will see nothing at all.
If you are blocked or repeatedly challenged and think that is wrong, write to support@meeto.me and a person will look at it.
We share personal data only with providers that help us run the Service, under contracts that limit what they may do with it. Our current providers:
| Provider | What for |
|---|---|
| Sign-in, and calendar access if you connect a calendar | |
| Cloudflare | Website and media delivery, and storage of recordings, transcripts and recaps |
| Stripe | Card payments, subscription billing, fraud checks on payments |
| OpenAI and Google | Speech-to-text and summarisation — turning meeting audio into transcripts and recaps, under a no-training commitment |
| A device-intelligence provider in our group | Bot detection and anti-abuse checks (section 6) |
| Error-monitoring and email-delivery providers | Diagnosing crashes; sending service emails such as recap notifications |
We keep an up-to-date list and will announce material changes to it. We also share data with our group companies where needed to run and support the Service, with professional advisers under confidentiality, and with a buyer or investor in connection with a corporate transaction, under confidentiality.
If a meeting type is assigned to a team workspace as a work meeting type, booking events for it (such as the guest's name and email, the time and the booking details) are delivered to webhook endpoints configured by the workspace owner — for example the organisation's CRM. From that point the organisation controls that copy of the data. Your personal meeting types are never shared with the workspace. If you book a team meeting with someone, your booking details reach the host's organisation the same way.
If someone wants a recording of a meeting, they should ask the host — the host chose to record it and controls the copies. Where the meeting belongs to an organisation’s account, we forward the request to that organisation.
We disclose data to law-enforcement or other authorities only on a request that is lawful, specific and binding on us in the United Arab Emirates. We give only the narrow set of data the request actually covers, we challenge requests that are overbroad or improperly served, and where the law allows it we tell the affected user first so they can respond.
Often there is simply nothing to give: if nobody turned on recording or AI, that meeting’s content was never stored anywhere we can retrieve it from. We cannot produce a recording of a meeting that was not recorded. Where we are legally required to preserve data, we may hold it beyond the periods in section 9 for as long as that requirement lasts, and no longer.
We are based in the United Arab Emirates, and our providers operate in several countries, so your data may be processed outside your own. Where we move personal data out of the EEA, the UK or Switzerland, we rely on appropriate safeguards — normally the European Commission’s Standard Contractual Clauses, together with the UK Addendum or the UK International Data Transfer Agreement where relevant — and on assessments of the destination country. You can ask us for details of the safeguards used for a specific transfer.
| Data | Kept for |
|---|---|
| Call media where nothing was recorded | Not stored at all |
| In-meeting chat | Deleted when the meeting ends |
| Cloud recordings (Pro) | Automatically deleted 90 days after the meeting; you can delete them sooner, and you are warned before they expire |
| Transcripts and AI recaps | Until the host deletes them, or the account is deleted |
| Meeting rooms created without an account | Expire after 24 hours without use |
| Meeting metadata (times, participant counts, display names) | While the host's account exists; for guest-only meetings, a limited period for security and capacity planning |
| Workspace webhook delivery logs | While the workspace exists; deleted when the workspace closes |
| Security, anti-abuse and diagnostic logs | 12 months |
| Account data | While your account exists, then deleted within 30 days |
| Billing and tax records | As long as UAE accounting and tax law requires, currently five years |
| Support correspondence | 24 months |
One exception applies to every row: where the law requires us to preserve specific data — for example under a preservation order — we keep that data for as long as the requirement lasts, and delete it when it ends.
We protect the Service with measures including encryption of media in transit, encryption of stored recordings, signed tokens for host rights and room access, access controls and least-privilege permissions for our own staff, logging, supplier reviews, and an incident-response process. No online service can promise absolute security. Use a strong Google account with two-factor authentication, and be careful where you share meeting and recap links.
If a personal data breach affecting you occurs, we will notify the relevant authority and affected people where the law requires, and without undue delay.
What you can do yourself, in account settings: delete a recording, delete a transcript or recap, delete a meeting page, disconnect a calendar, and delete your whole account.
What you can ask us for by email: a copy of the personal data we hold about you, a copy in a machine-readable format so you can move it elsewhere, correction of anything wrong, deletion, restriction of or objection to a particular use, and withdrawal of a consent you previously gave. These are rights the law gives you, so we honour them whether or not there is a button for them in the product. Write to support@meeto.me; we answer within 30 days and tell you if we need longer, and we may ask for enough information to be sure it is really you.
If the meeting content you are asking about sits in an organisation’s account, we will point you to that organisation and help it respond. Withdrawing consent does not undo processing that already happened. We will not treat you worse for exercising any of this.
You have the right to lodge a complaint with your national data-protection authority. We would rather you came to us first, at support@meeto.me, so we can put it right.
Data-protection laws differ, and some give you rights beyond those in section 11. Whatever the law where you live says you are entitled to, write to support@meeto.me and we will honour it.
Two things are true everywhere and worth stating plainly: we do not sell personal data, and we do not share it for advertising of any kind, cross-site or otherwise. We also honour Global Privacy Control signals sent by your browser for optional analytics.
We use essential cookies and local storage to keep you signed in, protect against abuse, and remember your camera, microphone and layout preferences between calls. We also use privacy-respecting product analytics to understand which features are used; where consent is required, we ask for it first and you can change your mind at any time. There are no advertising or cross-site tracking cookies on meeto.
The Service is not directed at children under 16, and accounts require you to be at least 16. We do not knowingly collect data from children below that age. If you believe a child has given us personal data, write to support@meeto.me and we will delete it.
We may update this policy. If a change is material we will give notice by email or in the product before it takes effect, and we will keep earlier versions available on request. The date at the top shows the current version.
KeepFlow L.L.C-FZ, Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E.
Privacy requests, complaints and everything else: support@meeto.me
We would rather hear from you first, but you can always complain to your local data-protection authority.